Security Basics mailing list archives

Re: bash_history


From: tmpgl () ispgaya pt
Date: Sat, 9 Apr 2005 19:01:20 +0100

And if you execute the bash with -noprofile?
like:
/bin/bash -noprofile -norc
then you can unset HISTFILE..

Quoting l0rd4gu1 <l0rd4gu1 () icontrol com mx>:

Hi Alex

Use readonly to define the variable & use chattr for files

/etc/profile:
.
.
readonly HISTFILE=......
.
.

Raul
--
Victorious warriors win first and then go to war, while defeated
warriors go to war first and then seek to win. -- Sun-Tzu

Alejandro Flores(alejandro.flores () triforsec com br)@2005.04.08
18:50:51 +0000:
Hey there,

I was googling about a way to protect the bash_history file from user
removal or UNSET the HISTFILE variable and all I found was papers about
disabling this file for security reasons. Weird! Why it's recommended to
disable this file, when it contains the history of typed commands from
all users? Ok, ok, you can tell me that users may have typed passwords
in a bash session to gain access to a mysql database for example.
But, if you need to do some forensics in your compromised server, this
file is the first place to know what the 'malicious dude' did to gain
root privileges, the server where he downloaded his craps, etc...
I started 'chown'ing the .bash_profile and .bashrc files to root, and
removed the 'wx' from group and others. The user has only read
permission.
But I can't prevent him from changing the HISTFILE variable. Like:
export HISTFILE=/dev/null
With this command, all my steps from now aren't recorded.

Ideas?

Regards,
Alejandro Flores

----------------------------------------------------------------
Este email foi enviado via o webmail do ISPGaya
Instituto Superior Politécnico Gaya



---------------------------------------------------------------------------
Earn your MS in Information Security ONLINE
Organizations worldwide are in need of highly qualified information security
professionals.  Norwich University is fulfilling this demand with its MS in
Information Security offered online.  Recognized by the NSA as an
academically excellent program, NU offers you the opportunity to earn your
degree without disrupting your home or work life.

http://www.msia.norwich.edu/secfocus_en
----------------------------------------------------------------------------


Current thread: